Appliance Recovery Following a Security Incident
Purpose
This section provides recovery guidance for Check Point Appliances following a suspected security incident. It addresses scenarios involving potential compromise of the Gaia operating system, unauthorized system modifications, malware, rootkits, or suspected compromise of Lights Out Management (LOM) functionality.
The guidance is intended to assist customers in restoring an appliance to a known-good state prior to returning it to service.
Before initiating recovery activities, we recommend evaluating whether system logs, memory captures, forensic images, or other evidence should be preserved as part of an incident investigation. Reinstallation procedures will overwrite information that could be relevant to forensic analysis or regulatory requirements.
Recovery Objectives
When a security compromise is suspected, the primary recovery objectives are:
-
Remove potentially unauthorized software, malware, or system modifications from the Gaia operating environment.
-
Restore the appliance to a known-good software state using trusted installation sources.
-
Independently evaluate and remediate the LOM Card subsystem, where present and applicable.
-
Validate appliance functionality prior to returning it to the production use.
-
Rotate potentially affected credentials, certificates, keys, tokens, and other authentication material, as applicable in your environment.
Gaia Recovery Procedures
Based on current product understanding, a full reinstallation performed with the ISOmorphic tool (sk65205) from a trusted installation source returns the Gaia operating system to a factory-equivalent software state. Malware, rootkits, or unauthorized modifications confined to the Gaia operating system, or software stack would generally be expected to be removed as part of this reinstallation process.
Recommended Recovery Actions:
-
Use only trusted and verified installation media obtained from authorized sources.
-
Perform an ISOmorphic installation of the Gaia operating system.
-
Restore the configuration only from trusted backups that predate the suspected compromise and have been reasonably validated, where available.
-
Install currently supported software versions, hotfixes, and security updates applicable to the deployed platform.
-
Follow procedures specific to the appliance model and software release.
-
Contact Check Point Support if uncertainty exists regarding the appropriate recovery approach.
Lights Out Management (LOM) Considerations
The LOM Card subsystem operates independently of the Gaia operating system and maintains its own firmware and management environment. Because reinstallation of the Gaia operating system does not affect the LOM Card firmware, recovery activities should evaluate the LOM Card subsystem separately whenever a hardware compromise is suspected.
Where supported for the applicable platform, reinstalling the LOM Card firmware may be included as part of a comprehensive recovery process.
Recommended Recovery Actions:
-
Include the LOM Card firmware reinstallation in recovery procedures where supported by the appliance model.
-
Install supported LOM Card firmware versions.
-
Verify the LOM Card configuration after recovery.
-
Review and update the LOM Card credentials as appropriate.
-
Restrict the LOM Card access to authorized management networks.
LOM Card Threat Considerations
The LOM Card interface generally requires connectivity and configuration before it can be used for operational management. Specific implementations and configuration options may vary by appliance model.
If the LOM Card interface is not connected to a network and is not reachable through an authorized management path, the available attack surface is reduced. However, because the Gaia operating system and the LOM Card operate independently, reinstallation of the Gaia operating system alone would not affect any hypothetical compromise that exists within the LOM Card itself.
For this reason, recovery procedures should treat the Gaia operating system and the LOM Card as separate components and consider remediation of both environments when attempting to establish a known-good state following a security incident.
As a general best practice:
-
Disconnect or isolate the LOM Card from production networks unless operationally required.
-
Limit the LOM Card access to designated management networks.
-
Reinstall the Gaia operating system from trusted installation media.
-
Reinstall the LOM Card firmware where applicable and supported.
-
Validate both environments before returning the appliance to service.
Validation Prior to Returning an Appliance to Service
After recovery activities have been completed, we recommend performing validation procedures before placing the appliance back into production.
A recovered appliance may generally be considered appropriate for return to service when:
-
The Gaia operating system has been reinstalled from a trusted media using the ISOmorphic tool.
-
The LOM Card firmware has been reinstalled where applicable and supported.
-
The appliance successfully boots into the recovered Gaia operating system.
-
Administrative access and required services function as expected.
-
Configuration has been restored from trusted sources.
-
Operational validation and security review do not identify remaining indicators of compromise.
-
Potentially affected administrator credentials, certificates, keys, tokens, and other authentication material have been rotated or replaced, as appropriate.
-
Applicable supported software and firmware updates have been installed.
Recovery Guidance Summary
In the event of a suspected compromise of a Check Point Appliance, we recommend performing an ISOmorphic reinstallation using trusted installation media to restore the Gaia operating system to a factory-equivalent software state. Because the LOM Card subsystem operates independently from the Gaia operating system, recovery activities should also evaluate and, where applicable and supported, reinstall the LOM Card firmware as part of a comprehensive remediation process.
After the Gaia operating system and the LOM Card have been restored to known-good states and validated through operational testing, the appliance may generally be considered appropriate for return to service following installation of applicable updates and rotation of potentially affected credentials. If a known-good state cannot be established, customers should contact Check Point Support and evaluate whether hardware replacement is appropriate.
Important Note
This guidance is provided for general informational purposes based on current product understanding. Recovery procedures and results may vary depending on the appliance model, software version, configuration, and nature of the incident. Customers should follow applicable Check Point documentation, use trusted installation sources, and validate the appliance before returning it to production. This guidance does not guarantee that every compromise will be detected or eliminated.